Re: Wheezy update of simplesamlphp?

2018-02-06 Thread Raphael Hertzog
Hi, On Sun, 04 Feb 2018, Ola Lundqvist wrote: > No worry. It was my mistake. I did not expect that someone else would > do triaging when I was at front desk. You did nothing wrong. I'll try > to be a little more observant next time. :-) Just to be clear. Abhijith did not have to do this since he

Re: upload simplesamlphp

2018-02-06 Thread Raphael Hertzog
Hi, On Mon, 05 Feb 2018, Abhijith PA wrote: > I prepared LTS security update for simplesamlphp. Basic functions also > tested in a wheezy machine. Please review and upload. Debdiff is > attached. FWIW I would help to build some confidence if you explained in a bit more details the tests that you

Re: Wheezy update of dokuwiki?

2018-02-06 Thread Mohammed Adnène TROJETTE
Le 2018-02-03 21:59, Ola Lundqvist a écrit : Dear maintainers, Dear Ola, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of dokuwiki: https://security-tracker.debian.org/tracker/CVE-2017-18123 Would you like to take care of this yourse

Re: dojo / CVE-2018-6561

2018-02-06 Thread Ola Lundqvist
Hi Brian I tend to agree with your analysis. Source edit mode seems to be a separate module. https://dojotoolkit.org/reference-guide/1.10/dijit/_editor/plugins/ViewSource.html I do not know whether that one is included or not. According to that module page it has filtering support to filter out

Re: exiv2 [was: January Report]

2018-02-06 Thread Ola Lundqvist
Hi As you have the patch ready it may be worth it as I guess it will take very limited time to build a package and upload. I do not see this as important though. If the CVE for this package is ignored for jessie I think we can safely ignore it for wheezy as well. As you can see from the rest of t

Fwd: simplesamlphp_1.9.2-1+deb7u2_amd64.changes REJECTED

2018-02-06 Thread Abhijith PA
Hi, I think someone uploaded to master ftp queue. :) Forwarded Message Subject: simplesamlphp_1.9.2-1+deb7u2_amd64.changes REJECTED Date: Mon, 05 Feb 2018 12:08:25 + From: Debian FTP Masters To: abhij...@openmailbox.org, Abhijith PA , Thijs Kinkhorst Uploads to oldoldsta

Upload mailman

2018-02-06 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello. I prepared a LTS security update for mailman. Debdiff is attached. link: https://mentors.debian.net/debian/pool/main/m/mailman/mailman_2.1.15-1+deb7u3.dsc I manually done following tests for finding regressions. - - Installed my build in a w

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Readd krb5 to dla-needed.txt

2018-02-06 Thread Brian May
Markus Koschany writes: > +krb5 > + NOTE: lts-do-not-call > +-- What does lts-do-not-call mean? -- Brian May

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Readd krb5 to dla-needed.txt

2018-02-06 Thread Abhijith PA
On Wednesday 07 February 2018 12:38 PM, Brian May wrote: > Markus Koschany writes: > >> +krb5 >> + NOTE: lts-do-not-call >> +-- > > What does lts-do-not-call mean? > See security-tracker/data/packages/lts-do-not-call .

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] add python2.6, 2.7 and claim 2.7

2018-02-06 Thread Brian May
Abhijith PA writes: > +python2.6 > +-- > +python2.7 (Abhijith PA) > +-- Hello, I see you have claimed Python2.7 but not Python2.6, which both have the same vulnerability. CVE-2018-130 Upstream have decided that this is not a security issue, and it has been marked no-DSA in Jessie and Stre

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Readd krb5 to dla-needed.txt

2018-02-06 Thread Brian May
Abhijith PA writes: > On Wednesday 07 February 2018 12:38 PM, Brian May wrote: >> Markus Koschany writes: >> >>> +krb5 >>> + NOTE: lts-do-not-call >>> +-- >> >> What does lts-do-not-call mean? >> > > See security-tracker/data/packages/lts-do-not-call . krb5 doesn't appear to be in this list

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] add python2.6, 2.7 and claim 2.7

2018-02-06 Thread Abhijith PA
Hi, On Wednesday 07 February 2018 12:54 PM, Brian May wrote: > > Hello, > > I see you have claimed Python2.7 but not Python2.6, which both have the > same vulnerability. CVE-2018-130 > > Upstream have decided that this is not a security issue, and it has been > marked no-DSA in Jessie and S